Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2rgh-8rcv-gfrg

больше 2 лет назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2rgh-6pcq-8cq4

больше 3 лет назад

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2rgh-3c29-qm63

почти 4 года назад

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2rgg-xfp9-8w6f

больше 3 лет назад

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.

EPSS: Средний
github логотип

GHSA-2rgg-v6c8-mc7v

почти 4 года назад

AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.

EPSS: Низкий
github логотип

GHSA-2rgf-ppf8-9r8x

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2rgc-px3m-hcr7

больше 3 лет назад

A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack.

EPSS: Низкий
github логотип

GHSA-2rg9-mqj3-xwq5

больше 1 года назад

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2rg9-gvg8-5qq3

больше 3 лет назад

Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

EPSS: Низкий
github логотип

GHSA-2rg9-797v-v3pv

9 месяцев назад

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2rg8-qgm4-g9hx

почти 4 года назад

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rg8-99xw-rc3j

около 4 лет назад

NETGEAR R8000 devices before 1.0.4.62 are affected by a buffer overflow by an authenticated user.

EPSS: Низкий
github логотип

GHSA-2rg6-xxcc-pvj5

12 месяцев назад

A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Delete Record Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rg6-p99m-m238

больше 3 лет назад

In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69384124.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2rg6-3m8g-8x9g

почти 4 года назад

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.

EPSS: Низкий
github логотип

GHSA-2rg6-2x33-4cjj

около 1 года назад

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2rg5-j2x6-vgmc

около 3 лет назад

Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2rg5-632f-rr5j

больше 3 лет назад

Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php.

EPSS: Низкий
github логотип

GHSA-2rg4-rjm2-69pg

около 3 лет назад

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2rg4-pr4v-2f84

11 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rgh-8rcv-gfrg

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rgh-6pcq-8cq4

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rgh-3c29-qm63

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.

CVSS3: 8.8
14%
Средний
почти 4 года назад
github логотип
GHSA-2rgg-xfp9-8w6f

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.

11%
Средний
больше 3 лет назад
github логотип
GHSA-2rgg-v6c8-mc7v

AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2rgf-ppf8-9r8x

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rgc-px3m-hcr7

A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rg9-mqj3-xwq5

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rg9-gvg8-5qq3

Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2rg9-797v-v3pv

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.

CVSS3: 4.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-2rg8-qgm4-g9hx

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2rg8-99xw-rc3j

NETGEAR R8000 devices before 1.0.4.62 are affected by a buffer overflow by an authenticated user.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2rg6-xxcc-pvj5

A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Delete Record Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-2rg6-p99m-m238

In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69384124.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rg6-3m8g-8x9g

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rg6-2x33-4cjj

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.

CVSS3: 3.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2rg5-j2x6-vgmc

Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
2%
Низкий
около 3 лет назад
github логотип
GHSA-2rg5-632f-rr5j

Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rg4-rjm2-69pg

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2rg4-pr4v-2f84

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

11 месяцев назад

Уязвимостей на страницу